Improper Authorization in Keycloak - CVE-2026-2733
Published: September 10, 2026
Vulnerability details
The vulnerability allows a remote user to obtain authentication tokens for a disabled Docker registry client.
The vulnerability exists due to improper authorization in the Docker v2 authentication endpoint when processing token requests for an administratively disabled Docker registry client. A remote privileged user can use previously valid credentials to obtain authentication tokens for a disabled Docker registry client.
Affected software
Red Hat build of Keycloak
How to mitigate CVE-2026-2733
Red Hat build of Keycloak - update to 26.4.10